According to the researcher: "The TLS connections are encrypted against tampering or eavesdropping. However, the application does not validate the server certificate properly while initializing the TLS connection. This allows for a network attacker to intercept the connection and read the data. The attacker could the either send the client a malicious response, or forward the (possibly modified) data to the real server."
Metrics
Affected Vendors & Products
References
History
Wed, 02 Oct 2024 17:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Google
Google nest Cam Battery Firmware Google nest Cam Floodlight Firmware Google nest Cam Indoor Firmware Google nest Doorbell Battery Firmware |
|
CPEs | cpe:2.3:o:google:nest_cam_battery_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:google:nest_cam_floodlight_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:google:nest_cam_indoor_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:google:nest_doorbell_battery_firmware:*:*:*:*:*:*:*:* |
|
Vendors & Products |
Google
Google nest Cam Battery Firmware Google nest Cam Floodlight Firmware Google nest Cam Indoor Firmware Google nest Doorbell Battery Firmware |
|
Metrics |
cvssV3_1
|
Wed, 02 Oct 2024 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | According to the researcher: "The TLS connections are encrypted against tampering or eavesdropping. However, the application does not validate the server certificate properly while initializing the TLS connection. This allows for a network attacker to intercept the connection and read the data. The attacker could the either send the client a malicious response, or forward the (possibly modified) data to the real server." | |
Weaknesses | CWE-269 | |
References |
|
MITRE
Status: PUBLISHED
Assigner: Google_Devices
Published: 2024-10-02T14:06:33.704Z
Updated: 2024-10-02T17:00:33.323Z
Reserved: 2024-08-19T16:32:38.650Z
Link: CVE-2024-44097
Vulnrichment
Updated: 2024-10-02T17:00:26.112Z
NVD
Status : Awaiting Analysis
Published: 2024-10-02T14:15:05.670
Modified: 2024-10-04T13:50:43.727
Link: CVE-2024-44097
Redhat
No data.